Referring to Figure 4-5, the safe state of the TMS320F28002x MCU is defined as the one in which:
- TMS320F28002x MCU Reset is asserted
- Power supply to TMS320F28002x MCU is disabled
using an external supervisor as a result of a critical failure. In general, a power supply
failure is not considered in detail in this analysis as it is assumed that the system
level functionality exists to manage this condition.
- External system is informed using one of C2000
MCU’s IO pins as a result of a check failure (for example, ERRORSTS pin is asserted).
- Output of the TMS320F28002x MCU driving the
actuator is forced to inactive mode as a result of a check failure (for example, GPIO pins
corresponding to the mission function is tri-stated).